wp-spec-to-goal
Pass
Audited by Gen Agent Trust Hub on Jul 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill generates shell commands for
wp-env,WP-CLI, andplaywright-cliintended for execution by a downstream agent. This includes the use ofwp evalandwp eval-file, which enable dynamic PHP code execution within a containerized WordPress environment.\n- [PROMPT_INJECTION]: The skill contains instructions inAGENTS.mdandVERIFY.mdadvising users or agent harnesses to 'pre-approve or bypass' sandboxes for toolsets like Docker and wp-env. This represents an attempt to influence the security configuration of the execution environment.\n- [PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection (Category 8).\n - Ingestion points: Untrusted data enters the context through user-provided 'rough WordPress plugin or feature ideas' as described in
SKILL.md.\n - Boundary markers: The generated
GOAL.mdandVERIFY.mdtemplates do not utilize boundary markers or instructions to disregard embedded commands in the interpolated user content.\n - Capability inventory: The skill can perform file-write operations (
scaffold-templates.md) and generate shell commands for subsequent execution (verify-template.md).\n - Sanitization: No evidence of sanitization, validation, or escaping of user-provided content before interpolation into templates was found.
Audit Metadata